fix: close open issues and fold in safe fixes from open PRs - #70
Draft
BIackFIame wants to merge 8 commits into
Draft
BIackFIame wants to merge 8 commits into
BIackFIame wants to merge 8 commits into
Conversation
This was referenced Sep 23, 2026
Provider CLI resolution is driven by declarative command definitions instead of assuming the executable matches the provider id. MiniMax Code (`mcode`), Antigravity (`agy`) and Cursor resolve through the same registry, known install directories, recheck and install links that howdeploy#52 introduced. Cursor prefers `cursor-agent`; a generic `agent` is accepted only when its real path is verified as Cursor, because Grok also installs an `agent` executable. Each new agent gets normal and resume launches where the CLI documents them, its YOLO flag only where one exists, launcher entries with a settings migration, its provider mark and session restore. MiniMax Code has no permission-bypass flag, so its YOLO profile launches the stock CLI and says so. Antigravity restores as a fresh session because it has no resumable id that CanvasTTY can persist. Provider ids, labels and launcher order live in a dependency-free `providerCatalog.ts` that `contracts.ts` re-exports, so the Even G2 companion bundle stays free of URLs outside its network whitelist; its phone launcher lists the new agents too. Lifecycle hooks are prepared only for providers that have a hook adapter, so the new agents never write Grok's shared hook configuration. ADR: docs/adr/ADR-20260921-provider-cli-command-definitions.md Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tion - Provider API keys are stored in the main process, encrypted with Electron safeStorage; the renderer only sees which keys exist. - API profiles name a model backend (protocol, HTTPS base URL, key reference, default model) with built-in presets. - Sessions carry role and parent metadata; restore drops orphaned subagents instead of resurrecting them. - Per-provider capability descriptors state what CanvasTTY can really do with each agent, and agent control (spawn, send, observe, result, cancel, children) works over ordinary terminal sessions. - An orchestration MCP surface rides the existing agent-bridge design: authenticated user-local socket, one-use bootstrap capabilities, scoping to the caller's own session subtree, and MCP injection for Claude, Codex, OpenCode, Kimi and Hermes. Only orchestrator sessions receive it; ordinary launches are unchanged. ADR: docs/adr/ADR-20260921-orchestration-mcp-rides-agent-bridge.md Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…accounts - Saved remote hosts use the system OpenSSH client (BatchMode, no stored passwords) for connectivity checks, remote terminals, CLI discovery, light load/memory metrics and per-host workspace mapping. - Automatic placement applies hard filters (reachability, provider rules, workspace mapping, capacity) before ranking by load and free memory, and probes whether each provider's API answers from that host. - spawn_agent can request a host, so subagents may run remotely. - Data-handling tiers D0-D3 are enforced at spawn time, with host confidentiality ceilings and repository path policies. - Several accounts per provider with subscription tiers; each account is bound to its own computer. - Security fixes: lease supersession, an authentication hang and SSH option injection through host fields. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Bounded task capsules and workspace sandbox plans; protected mounts are rejected and hidden edits are retained. - One live launch policy for create, restart and restore, enforcing account host affinity, budgets and privacy before every spawn. - Bounded host probes that honour account placement. - Accounts launch their bound model with isolated API credentials; Kimi homes and OpenCode API protocols are aligned. - Durable isolated git worktrees that preserve agent output. - Configured Docker/Podman containers run with durable owned workspaces, a fixed Python bootstrap that verifies limits, capabilities and mounts before exec, and cleanup fenced against pending creation. - A responsive API profile editor and launcher controls for workspaces and containers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Local ACP conversations and lifecycle for Kimi, Cursor and MiniMax, with model selection confirmed before prompts are admitted. - Settings gain account connections, host controls, explicit account launch routing and responsive navigation. - Remote API agents run in containers with host-local credentials; retained remote output can be reviewed and exported. - Capsules retain output, launch only verified selected files in owned containers, apply reviewed snapshots and run saved checks in isolated snapshots; orchestration is scoped to live parent authority. - Initial tasks are delivered through literal startup arguments instead of typed PTY input. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Stored project preferences with scopes, delivered to agents through fixed launch routes with a route preview. - Live imports of project conventions (AGENTS.md, CLAUDE.md, Cursor rules with bounded frontmatter parsing) and design token editing. - Learning from explicit corrections and accepted changes, checks of reviewed changes against project conventions, and explicit read-only agent review of capsule patches. - Container inventory and launch previews across computers, with complete eligible routes launched through the shared policy gates. - Keyboard focus and control visibility fixes; explicit delegation. The Browser card is unchanged, per the maintainer's browser freeze. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BIackFIame
force-pushed
the
stack/8-final
branch
from
September 23, 2026 14:26
ff9d8de to
bedc0a5
Compare
…nd sign-in - Opt-in decision routing: rules first, optional Jev evaluation. Routes are assembled automatically from accounts, hosts and installed CLIs, ordered by task difficulty, and weigh cost, quality and limit headroom. Jev responses are validated tolerantly and the evaluator budget is reserved before waiting. - Reasoning effort is a launch dimension (Claude --effort, Codex model_reasoning_effort, Grok --reasoning-effort) and changes the cost/quality estimate of a route. - "Prepare server" and "Prepare all servers" install base packages and only the agents whose API answers from that server, adding swap on small machines and verifying it is active. - An API key held in the app can be forwarded per launch to any saved server over SSH stdin into a 0600 tmpfs file that is deleted before exec; it never appears in argv or on disk. - Codex and Claude subscription accounts sign in once through the app, on the computer the account is bound to. - Launchers keep agents that have a remote or container route even without a local CLI. - The launch dialog offers an explicit Orchestrator option (disabled with an explanation for agents without an orchestration adapter), cards show Orchestrator or Subagent, and a delegation chain whose root the person launched as an orchestrator carries that consent: implicit floors warn, explicit classes, path policies, capsules and containers stay enforced. - Direct launches on the default data class warn instead of blocking, including the recheck before spawn, restart and restore of a session whose task the person typed; delegated and automated launches stay blocked. - Remote terminals open the server's own login shell in the mapped folder; Cursor's reachability probe uses its real API host; servers without curl are no longer excluded; Podman's read-only /run/.containerenv mount is accepted by the container bootstrap. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Final part of the stack. It resolves what no other pull request resolves and adopts the fixes from stalled pull requests that do not fall under a maintainer exclusion. - Issue howdeploy#53: the HOME clock shows the localized date under the time. - Issue howdeploy#22: the plugin showcase and search work anonymously, following the issue's preferred baseline. GitHub sign-in is explained as optional before it starts. A rate-limit error names when to retry. The release workflow warns when no OAuth client ID is configured. - From howdeploy#51: hook stdin is read up to 512 KiB, so a long final answer keeps its turn id and bounded text. - From howdeploy#35: the default session denies web permissions, a crashed renderer reloads in place, lost child processes are logged, and the secret audit also scans the built bundle and Windows home paths. - An Unreleased changelog section describes the whole stack in EN/RU/ZH. Co-authored-by: SHEM <arxipov-pavel@mail.ru> Co-authored-by: s079891 <mail@4544.ru> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BIackFIame
force-pushed
the
stack/8-final
branch
from
September 23, 2026 16:46
bedc0a5 to
3b3674a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal
Final part of the stack. It closes what no other pull request closes, adopts the safe fixes from stalled pull requests that no maintainer ruling excludes, and records the state of every open upstream pull request and issue in one place.
Behavior
CANVASTTY_GITHUB_CLIENT_IDis unset.76bbaf5): hook stdin is read up to 512 KiB, so a long final answer keeps its turn id and a bounded, surrogate-safe answer. Before this, a Stop payload over 16 KiB was dropped whole.be052b2): the default session denies web permissions (the Browser keeps its own partition), a crashed renderer reloads in place, and lost child processes are logged. The secret audit also scans the builtout/bundle and Windows home paths, and runs after release builds. feat(app): deny default permissions, recover the renderer, gate hidden output, notify and self-update #35's updater is not included; feat(updates): add GitHub release updates across platforms #62 covers updates.Unreleasedsection summarizes the whole stack in EN, RU and ZH.Original authors are credited with
Co-authored-bytrailers.Order: open pull requests and issues
omp acprun first.Follow-up #62 needs once both land:
shuttingDown;SettingsLocation.Series
Each part is one commit on top of the previous one. Please merge them in order. Until #69 is merged, GitHub also shows the earlier parts here; review only the top commit
3b3674a(Commits tab → last commit).Compatibility with open upstream PRs
integration/stack-with-open-prsis this whole stack with #54–#62 merged on top and every conflict resolved. On that branch both TypeScript checks, 1492/1492 tests,npm run test:even(47/47) andelectron-vite buildpass.SettingsStore.ts. Keep this stack's store: it already serializes every write and publishes a value only after the disk write succeeds. fix(settings): keep rejected writes out of live settings #58's new tests pass against it unchanged.registerIpcreturns the window observer; keep both sides. This stack's IPC tests stub both window-state helpers, so they pass in either merge order.TerminalManager.ts: keep this stack's launch structure. The answer-capture grant must also reach the prepared and measured-grid first start, because every real agent launch goes through that path.hook-helper.mjs: keep this stack's 512 KiB input read and safe cut, and gate the answer on fix(even-g2): require explicit grant for answer capture #55's grant.64ef294(grant through prepared starts, feat(updates): add GitHub release updates across platforms #62 follow-ups) andc2dd726(hook test under the grant).shutdownForUpdatemust clearshuttingDown. Otherwise no session can start after a failed update; feat(updates): add GitHub release updates across platforms #62's own test fails without this.SettingsLocation.I will rebase this stack onto whichever of these lands first.
Verification
npm run test:even(47/47),npm run buildandnpm run audit:secretspass. The audit covers both the source tree and the built bundle.🤖 Generated with Claude Code